Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium

A global organization uses Prisma Cloud to enforce compliance with GDPR across its AWS, Azure, and GCP environments. They have a specific requirement to identify all storage buckets that are publicly accessible AND are located in a region outside of the EU. Which RQL attribute is crucial for filtering resources based on their geographical location?

  1. Aresource.name
  2. Baccount.id
  3. Cregion
  4. DpublicAccess.level
Show answer & explanation

Correct answer: C. region

The 'region' attribute in RQL allows users to filter resources based on their deployment region, which is essential for enforcing data residency requirements like those implied by GDPR for EU data.

Why the other options are wrong

  • A. resource.name filters by the name of the resource, not its physical location.
  • B. account.id filters by the cloud account, not the geographical region within an account.
  • D. publicAccess.level filters by public accessibility, which is one part of the requirement but doesn't address geographical location.

RQL Region Attribute

The 'region' attribute in Resource Query Language (RQL) allows users to filter and query cloud resources based on their geographical deployment region, enabling enforcement of data residency and compliance with regional regulations.

  • Filters resources by geographic location.
  • Crucial for data residency compliance (e.g., GDPR).
  • Applicable across all supported cloud providers.

Memory trick: For location, look to the 'region'.

More Cloud Security Posture Management (CSPM) questions